Suspicious
Suspect

PE Executable
MD5: 07d26439c570d6f309b451ce2ed2180e
Size: 726.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 07d26439c570d6f309b451ce2ed2180e
Sha1 69476f8856199fc9ec543faeb19dcecd9abc9d9c
Sha256 1ea022e39cb9cf37fbfdc1f6b2b4cd2dff64793c981312963894ecf2d34587a9
Sha384 96981e32206e123296dba0ac05baa6e95bfaf9a8a2414865816b8e2da0efcef849f63739da2fd34e599c48f7aaa0e144
Sha512 d468ebe9d84d0f42675efa782cf236fee6210b4783ddf236f43aaf84bf53dfc0c072d1f14de58cbeace7866f5fdb5ee64a68a538d63b11a42481bfe9c5d3257e
SSDeep 12288:xY3HU9CqeVBatQEjSKKgslti3rWRXZcQH/91tfa73F3UDjXD8edxz6s:W3HUc5VB82yWRXZcQf91taFS0C4s
TLSH 55F40210276ACE11C0BA67B11870D37113B9AE8DA526D21B4FFABCEF787AF052558353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
wZRtJE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
lRSPOc.exe
Full Name
lRSPOc.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
lRSPOc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lRSPOc
Assembly Version
3.2.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
lRSPOc.exe
Full Name
lRSPOc.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
lRSPOc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lRSPOc
Assembly Version
3.2.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
wZRtJE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙